That sounds an awful lot like the author thinks that what they were doing is fraudulent. But I seem to have misplaced my Law Degree, so I couldn't say.
Personally, I am not sympathetic with attempts to "hack" a business' systems, whether by social engineering, attempting to exploit loopholes, or full-on exploiting security vulnerabilities. It may be legal, I cannot say, but when done in bad faith it is nothing more than parasitism. Or if you prefer, "exploitative."
Now of course, if the author has no intention of using these fraudulently obtained promo codes, and this is supposed to be some kind of white-hat "security research," that's another matter.
But this doesn't really look like it is being conducted for public benefit, e.g. to protect the privacy of users. And unsolicited testing of other people's systems seems like a legally perilous activity.